CVE-2015-2657
published 2015-07-16CVE-2015-2657: Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, and 6.3.0 through 6.3.7 allows…
PriorityP417medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.45%
70.3th percentile
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, and 6.3.0 through 6.3.7 allows remote authenticated users to affect confidentiality via unknown vectors related to Business Process Automation.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | supply_chain_products_suite | — | — |
| oracle | supply_chain_products_suite | — | — |
| oracle | supply_chain_products_suite | — | — |
| oracle | supply_chain_products_suite | — | — |
| oracle | supply_chain_products_suite | — | — |
| oracle | supply_chain_products_suite | — | — |
| oracle | supply_chain_products_suite | — | — |
| oracle | supply_chain_products_suite | — | — |
| oracle | supply_chain_products_suite | — | — |
| oracle | supply_chain_products_suite | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-7214 Mozilla: Cross-site reading attack through data: and view-source: URIs (MFSA 2015-149)
bugzilla·2015-12-15·CVSS 5.0
CVE-2015-7214 [MEDIUM] CVE-2015-7214 Mozilla: Cross-site reading attack through data: and view-source: URIs (MFSA 2015-149)
CVE-2015-7214 Mozilla: Cross-site reading attack through data: and view-source: URIs (MFSA 2015-149)
Security researcher Tsubasa Iinuma reported a mechanism to violate same-origin policy to content using data: and view-soure: URIs to confuse protections and bypass restrictions. This resulted in the ability to read data from cross-site URLs and local files.
External Reference:
https://www.mozilla.org/security/announce/2015/mfsa2015-149.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Tsubasa Iinuma as the original reporter.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 5
Via RHSA-2015:2657 https://rhn.redhat.co
Bugzilla
CVE-2015-7205 Mozilla: Underflow through code inspection (MFSA 2015-145)
bugzilla·2015-12-15·CVSS 10.0
CVE-2015-7205 [CRITICAL] CVE-2015-7205 Mozilla: Underflow through code inspection (MFSA 2015-145)
CVE-2015-7205 Mozilla: Underflow through code inspection (MFSA 2015-145)
Security researcher Ronald Crane reported an underflow found through code inspection. This does not all have a clear mechanism to be exploited through web content but could be vulnerable if a means can be found to trigger it.
External Reference:
https://www.mozilla.org/security/announce/2015/mfsa2015-145.html
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Ronald Crane as the original reporter.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 5
Via RHSA-2015:2657 https://rhn.redhat.com/errata/RHSA-2015-2657.html
---
This issue has been address
2015-07-16
Published